First published: Sun Feb 05 2012(Updated: )
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z710e GRI40, Sensation 4G GRI40, Desire S GRI40, EVO 3D GRI40, and EVO 4G GRI40 allow remote attackers to obtain 802.1X Wi-Fi credentials and SSID via a crafted application that uses the android.permission.ACCESS_WIFI_STATE permission to call the toString method on the WifiConfiguration class.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
HTC Desire HD | =frg83d | |
HTC Desire HD | =gri40 | |
HTC Desire S | =gri40 | |
HTC Droid Incredible | =frf91 | |
HTC EVO 3D | =gri40 | |
HTC EVO 4G | =gri40 | |
HTC Glacier | =frg83 | |
HTC Sensation Z710e | =gri40 | |
HTC Sensation 4G | =gri40 | |
HTC Thunderbolt | =frg83d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4872 is considered to have a medium severity rating due to its potential to allow remote attackers access to sensitive Wi-Fi credentials.
To mitigate CVE-2011-4872, updating the affected HTC devices to the latest available firmware is recommended.
CVE-2011-4872 affects multiple HTC Android devices including the Desire HD, Droid Incredible, Evo 3D, and Sensation series.
CVE-2011-4872 involves a remote attack where an attacker can obtain 802.1X Wi-Fi credentials and SSIDs.
CVE-2011-4872 remains a relevant vulnerability for users of the affected HTC devices that haven't been updated.